Welcome | Sign In
CRMBuyer.com
Product News

Oracle Rolls Out 51 Security Patches

Print Version
E-Mail Article
Reprints
Oracle Rolls Out 51 Security Patches

Oracle released a new Critical Patch Update addressing 51 security flaws across a variety of its products. Twenty-six of the patches are for Oracle Database products, many of them addressing vulnerabilities to remote intrusion without a user name or password. The update also includes non-security fixes that are required by the security patches.


Run Your Entire Contact Center in the Cloud
Many businesses are increasingly seeking ways to improve the quality, flexibility, and scalability of their traditional call centers. Download this free white paper and learn the top 8 reasons to consider going virtual.

Oracle (Nasdaq: ORCL) on Tuesday released a new Critical Patch Update addressing 51 security flaws across a variety of its products. The release was Oracle's ninth such quarterly update, and was the first to be preannounced. The release was initially announced last Thursday.

Included among the patches are security fixes for Oracle Database Server, Oracle Applications Server, Oracle Collaboration Suite, Oracle E-Business Suite, Oracle Enterprise Manager and Oracle PeopleSoft Enterprise Applications.

Twenty-six of the patches are for Oracle Database products, many of them addressing vulnerabilities to remote intrusion without a user name or password. The update also includes non-security fixes that are required by the security patches. The company recommends that customers apply all patches promptly.

52 Minus 1

Although the preannouncement had indicated that 52 patches would be released, one was withheld at the last minute after a technical problem was discovered, according to a blog written by Eric Maurice, manager for security in Oracle's Global Technology Business Unit.

"Per our policy, which is intended to ensure that all customers have an equal security posture, we removed the fix from the January CPU," Maurice said. The missing patch will be released in the next Critical Patch Update, due in April, he added. The last Critical Patch Update, released in October, included 101 fixes.

Starting last October, Redwood Shores, Calif.-based Oracle expanded its Critical Patch Update documentation to include executive summaries and common vulnerability scoring system (CVSS) scores to reflect the severity of the security flaws being addressed. It also began explicitly identifying vulnerabilities that could be remotely exploitable without authentication via user name and password.

By preannouncing the patches coming in forthcoming updates and providing expanded information about what they will entail, the company hopes to help customers be better prepared and keep their data safe.

Listening to the Customers

"Oracle introduced these changes as the result of feedback we received from many of our customers," Maurice explained. "We hope that these changes will help our customers assess the criticality of the vulnerabilities resolved with each [update] and help them obtain patching decisions from their senior management more quickly.

"Ultimately, we feel these changes should result in further strengthening the security posture of our clients by providing a standard approach to vulnerability scoring and a means for better internal communication."

The improved communication with customers seems to be a strategy Oracle has embraced following its acquisition of PeopleSoft, Siebel and others, and is bound to improve customer Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse relations, noted Rebecca Wettemann, vice president of research for Nucleus Research.

"I think it's a great move on Oracle's part," Wettemann said. "The more they can help customers plan for the future, the happier and more loyal those customers will be."


Print Version E-Mail Article Reprints More by Katherine Noyes


Related News Alerts

Oracle Activate Alert | Search Archives

More by Katherine Noyes

Does Wine Make Linux Too Loose?
November 05, 2009
For those Wine aficionados out there, beware of the remote possibility that your Linux system could be infected by Windows-seeking malware. "WINE running a Windows virus is nothing more than a 'stupid Linux trick' ... for now," said Slashdot blogger hairyfeet. But if the year of the Linux desktop ever arrives, he wonders, can Linux hold up to a "tidal wave of stupidity"?
PayPal Gets Friendly With Developers
November 04, 2009
PayPal is aiming to remove some of the obstacles to wider use of its service by giving developers the tools they need to embed its functionality directly in applications. That means a user could make a purchase without leaving a mobile game, for example. "The network is the platform on which the potential of digital money will be fully realized," said PayPal President Scott Thompson.
Firefox 3.6 Tweaks Are Mostly Under the Hood
November 03, 2009
For users, Mozilla's new Firefox 3.6 beta includes personas -- a new feature for changing Firefox skins -- and it sends alerts when it encounters out-of-date plug-ins. Developers may be more interested in some of the more subtle changes, however -- e.g., support for new CSS, DOM and HTML5 Web technologies, as well as support for image rendering and multiple background images.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network